Remote Code Execution in Liferay Portal and Liferay DXP Products
CVE-2025-3586

7.5HIGH

Key Information:

Vendor

Liferay

Status
Vendor
CVE Published:
1 September 2025

What is CVE-2025-3586?

In specific versions of Liferay Portal and Liferay DXP, the Objects module fails to restrict Groovy scripts for Admin Users, enabling remote authenticated administrators to execute arbitrary code. This vulnerability poses significant security risks as it allows for unauthorized execution of scripts, potentially compromising the integrity of the affected systems. In contrast, Liferay DXP configurations do not permit Groovy in Object actions, highlighting the importance of version management and security settings.

Affected Version(s)

DXP 7.4.13-u27 <= 7.4.13-u42

DXP 2023.Q3.1 <= 2023.Q3.10

DXP 2023.Q4.0 <= 2023.Q4.10

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-3586 : Remote Code Execution in Liferay Portal and Liferay DXP Products